feat(scripts): snapshot opentofu state before and after tofu apply #472
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!472
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/tofu-apply-snapshot"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
OpenTofu state is local and encrypted with no remote backend, so a bad apply had no rollback point.
scripts/tofu-apply.shwrapstofu apply:terraform.tfstate, its.backupandterraform.tfvarsintoopentofu/state-snapshots/<utc>-<sha>/before the apply and again (-post) after it, exiting with apply's code.--restore <dir>replays a snapshot after a typed confirmation and refuses on uncommittedopentofu/*.tofuchanges.--self-testexercises snapshot, prune and restore against a temp copy.pnpm tofu:applynow runs the wrapper.opentofu/state-snapshots/is gitignored. No production apply is involved; the snapshots stay on the operator machine (off-site copy is #470).Checks
scripts/tofu-apply.sh --self-test(6/6), shellcheck on the script.